Mercurial > dovecot > original-hg > dovecot-1.2
annotate src/login-common/ssl-proxy-openssl.c @ 1544:ac6ee442376d HEAD
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
"key not found from hash" if SSL handshake fails.
author | Timo Sirainen <tss@iki.fi> |
---|---|
date | Thu, 12 Jun 2003 02:26:13 +0300 |
parents | 383d87166963 |
children | 545f6b150e2c |
rev | line source |
---|---|
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
1 /* Copyright (C) 2002 Timo Sirainen */ |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
2 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
3 #include "common.h" |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
4 #include "ioloop.h" |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
5 #include "network.h" |
1231 | 6 #include "hash.h" |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
7 #include "ssl-proxy.h" |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
8 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
9 #ifdef HAVE_OPENSSL |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
10 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
11 #include <openssl/crypto.h> |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
12 #include <openssl/x509.h> |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
13 #include <openssl/pem.h> |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
14 #include <openssl/ssl.h> |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
15 #include <openssl/err.h> |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
16 |
1544
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
17 #define SSL_CIPHER_LIST "ALL:!LOW" |
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
18 |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
19 enum ssl_io_action { |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
20 SSL_ADD_INPUT, |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
21 SSL_REMOVE_INPUT, |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
22 SSL_ADD_OUTPUT, |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
23 SSL_REMOVE_OUTPUT |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
24 }; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
25 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
26 struct ssl_proxy { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
27 int refcount; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
28 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
29 SSL *ssl; |
1235 | 30 struct ip_addr ip; |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
31 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
32 int fd_ssl, fd_plain; |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
33 struct io *io_ssl_read, *io_ssl_write, *io_plain_read, *io_plain_write; |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
34 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
35 unsigned char plainout_buf[1024]; |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
36 unsigned int plainout_size; |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
37 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
38 unsigned char sslout_buf[1024]; |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
39 unsigned int sslout_size; |
1458
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
40 |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
41 unsigned int handshaked:1; |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
42 unsigned int destroyed:1; |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
43 }; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
44 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
45 static SSL_CTX *ssl_ctx; |
1230
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
46 static struct hash_table *ssl_proxies; |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
47 |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
48 static void plain_read(void *context); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
49 static void plain_write(void *context); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
50 static void ssl_write(struct ssl_proxy *proxy); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
51 static void ssl_step(void *context); |
1458
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
52 static void ssl_proxy_destroy(struct ssl_proxy *proxy); |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
53 static int ssl_proxy_unref(struct ssl_proxy *proxy); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
54 |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
55 static void ssl_set_io(struct ssl_proxy *proxy, enum ssl_io_action action) |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
56 { |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
57 switch (action) { |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
58 case SSL_ADD_INPUT: |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
59 if (proxy->io_ssl_read != NULL) |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
60 break; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
61 proxy->io_ssl_read = io_add(proxy->fd_ssl, IO_READ, |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
62 ssl_step, proxy); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
63 break; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
64 case SSL_REMOVE_INPUT: |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
65 if (proxy->io_ssl_read != NULL) { |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
66 io_remove(proxy->io_ssl_read); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
67 proxy->io_ssl_read = NULL; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
68 } |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
69 break; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
70 case SSL_ADD_OUTPUT: |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
71 if (proxy->io_ssl_write != NULL) |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
72 break; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
73 proxy->io_ssl_write = io_add(proxy->fd_ssl, IO_WRITE, |
1457 | 74 ssl_step, proxy); |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
75 break; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
76 case SSL_REMOVE_OUTPUT: |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
77 if (proxy->io_ssl_write != NULL) { |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
78 io_remove(proxy->io_ssl_write); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
79 proxy->io_ssl_write = NULL; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
80 } |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
81 break; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
82 } |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
83 } |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
84 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
85 static void plain_block_input(struct ssl_proxy *proxy, int block) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
86 { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
87 if (block) { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
88 if (proxy->io_plain_read != NULL) { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
89 io_remove(proxy->io_plain_read); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
90 proxy->io_plain_read = NULL; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
91 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
92 } else { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
93 if (proxy->io_plain_read == NULL) { |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
94 proxy->io_plain_read = io_add(proxy->fd_plain, IO_READ, |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
95 plain_read, proxy); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
96 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
97 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
98 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
99 |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
100 static void plain_read(void *context) |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
101 { |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
102 struct ssl_proxy *proxy = context; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
103 ssize_t ret; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
104 |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
105 if (proxy->sslout_size == sizeof(proxy->sslout_buf)) { |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
106 /* buffer full, block input until it's written */ |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
107 plain_block_input(proxy, TRUE); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
108 return; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
109 } |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
110 |
1490 | 111 proxy->refcount++; |
112 | |
1458
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
113 while (proxy->sslout_size < sizeof(proxy->sslout_buf) && |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
114 !proxy->destroyed) { |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
115 ret = net_receive(proxy->fd_plain, |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
116 proxy->sslout_buf + proxy->sslout_size, |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
117 sizeof(proxy->sslout_buf) - |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
118 proxy->sslout_size); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
119 if (ret <= 0) { |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
120 if (ret < 0) |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
121 ssl_proxy_destroy(proxy); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
122 break; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
123 } else { |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
124 proxy->sslout_size += ret; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
125 ssl_write(proxy); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
126 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
127 } |
1490 | 128 |
129 ssl_proxy_unref(proxy); | |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
130 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
131 |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
132 static void plain_write(void *context) |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
133 { |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
134 struct ssl_proxy *proxy = context; |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
135 ssize_t ret; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
136 |
1490 | 137 proxy->refcount++; |
138 | |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
139 ret = net_transmit(proxy->fd_plain, proxy->plainout_buf, |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
140 proxy->plainout_size); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
141 if (ret < 0) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
142 ssl_proxy_destroy(proxy); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
143 else { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
144 proxy->plainout_size -= ret; |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
145 memmove(proxy->plainout_buf, proxy->plainout_buf + ret, |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
146 proxy->plainout_size); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
147 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
148 if (proxy->plainout_size > 0) { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
149 if (proxy->io_plain_write == NULL) { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
150 proxy->io_plain_write = |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
151 io_add(proxy->fd_plain, IO_WRITE, |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
152 plain_write, proxy); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
153 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
154 } else { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
155 if (proxy->io_plain_write != NULL) { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
156 io_remove(proxy->io_plain_write); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
157 proxy->io_plain_write = NULL; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
158 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
159 } |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
160 |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
161 ssl_set_io(proxy, SSL_ADD_INPUT); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
162 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
163 |
1490 | 164 ssl_proxy_unref(proxy); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
165 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
166 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
167 static const char *ssl_last_error(void) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
168 { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
169 unsigned long err; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
170 char *buf; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
171 size_t err_size = 256; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
172 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
173 err = ERR_get_error(); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
174 if (err == 0) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
175 return strerror(errno); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
176 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
177 buf = t_malloc(err_size); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
178 buf[err_size-1] = '\0'; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
179 ERR_error_string_n(err, buf, err_size-1); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
180 return buf; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
181 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
182 |
1235 | 183 static void ssl_handle_error(struct ssl_proxy *proxy, int ret, const char *func) |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
184 { |
1235 | 185 const char *errstr; |
186 int err; | |
187 | |
188 err = SSL_get_error(proxy->ssl, ret); | |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
189 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
190 switch (err) { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
191 case SSL_ERROR_WANT_READ: |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
192 ssl_set_io(proxy, SSL_ADD_INPUT); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
193 break; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
194 case SSL_ERROR_WANT_WRITE: |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
195 ssl_set_io(proxy, SSL_ADD_OUTPUT); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
196 break; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
197 case SSL_ERROR_SYSCALL: |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
198 /* eat up the error queue */ |
1235 | 199 if (verbose_ssl) { |
200 if (ERR_peek_error() != 0) | |
201 errstr = ssl_last_error(); | |
202 else { | |
203 if (ret == 0) | |
204 errstr = "EOF"; | |
205 else | |
206 errstr = strerror(errno); | |
207 } | |
208 | |
209 i_warning("%s syscall failed: %s [%s]", | |
1485
8c28289a15a1
s/host/addr/ in a few network functions
Timo Sirainen <tss@iki.fi>
parents:
1458
diff
changeset
|
210 func, errstr, net_ip2addr(&proxy->ip)); |
1235 | 211 } |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
212 ssl_proxy_destroy(proxy); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
213 break; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
214 case SSL_ERROR_ZERO_RETURN: |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
215 /* clean connection closing */ |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
216 ssl_proxy_destroy(proxy); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
217 break; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
218 case SSL_ERROR_SSL: |
1235 | 219 if (verbose_ssl) { |
220 i_warning("%s failed: %s [%s]", func, ssl_last_error(), | |
1485
8c28289a15a1
s/host/addr/ in a few network functions
Timo Sirainen <tss@iki.fi>
parents:
1458
diff
changeset
|
221 net_ip2addr(&proxy->ip)); |
1235 | 222 } |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
223 ssl_proxy_destroy(proxy); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
224 break; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
225 default: |
1235 | 226 i_warning("%s failed: unknown failure %d (%s) [%s]", |
1485
8c28289a15a1
s/host/addr/ in a few network functions
Timo Sirainen <tss@iki.fi>
parents:
1458
diff
changeset
|
227 func, err, ssl_last_error(), net_ip2addr(&proxy->ip)); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
228 ssl_proxy_destroy(proxy); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
229 break; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
230 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
231 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
232 |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
233 static void ssl_handshake(struct ssl_proxy *proxy) |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
234 { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
235 int ret; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
236 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
237 ret = SSL_accept(proxy->ssl); |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
238 if (ret != 1) |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
239 ssl_handle_error(proxy, ret, "SSL_accept()"); |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
240 else { |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
241 proxy->handshaked = TRUE; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
242 |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
243 ssl_set_io(proxy, SSL_ADD_INPUT); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
244 plain_block_input(proxy, FALSE); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
245 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
246 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
247 |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
248 static void ssl_read(struct ssl_proxy *proxy) |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
249 { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
250 int ret; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
251 |
1458
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
252 while (proxy->plainout_size < sizeof(proxy->plainout_buf) && |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
253 !proxy->destroyed) { |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
254 ret = SSL_read(proxy->ssl, |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
255 proxy->plainout_buf + proxy->plainout_size, |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
256 sizeof(proxy->plainout_buf) - |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
257 proxy->plainout_size); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
258 if (ret <= 0) { |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
259 ssl_handle_error(proxy, ret, "SSL_read()"); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
260 break; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
261 } else { |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
262 proxy->plainout_size += ret; |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
263 plain_write(proxy); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
264 } |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
265 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
266 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
267 |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
268 static void ssl_write(struct ssl_proxy *proxy) |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
269 { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
270 int ret; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
271 |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
272 ret = SSL_write(proxy->ssl, proxy->sslout_buf, proxy->sslout_size); |
1215 | 273 if (ret <= 0) |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
274 ssl_handle_error(proxy, ret, "SSL_write()"); |
1215 | 275 else { |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
276 proxy->sslout_size -= ret; |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
277 memmove(proxy->sslout_buf, proxy->sslout_buf + ret, |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
278 proxy->sslout_size); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
279 |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
280 ssl_set_io(proxy, proxy->sslout_size > 0 ? |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
281 SSL_ADD_OUTPUT : SSL_REMOVE_OUTPUT); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
282 plain_block_input(proxy, FALSE); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
283 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
284 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
285 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
286 static void ssl_step(void *context) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
287 { |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
288 struct ssl_proxy *proxy = context; |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
289 |
1458
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
290 proxy->refcount++; |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
291 |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
292 if (!proxy->handshaked) |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
293 ssl_handshake(proxy); |
1458
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
294 |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
295 if (proxy->handshaked) { |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
296 if (proxy->plainout_size == sizeof(proxy->plainout_buf)) |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
297 ssl_set_io(proxy, SSL_REMOVE_INPUT); |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
298 else |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
299 ssl_read(proxy); |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
300 |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
301 if (proxy->sslout_size == 0) |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
302 ssl_set_io(proxy, SSL_REMOVE_OUTPUT); |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
303 else |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
304 ssl_write(proxy); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
305 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
306 |
1458
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
307 ssl_proxy_unref(proxy); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
308 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
309 |
1235 | 310 int ssl_proxy_new(int fd, struct ip_addr *ip) |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
311 { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
312 struct ssl_proxy *proxy; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
313 SSL *ssl; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
314 int sfd[2]; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
315 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
316 if (!ssl_initialized) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
317 return -1; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
318 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
319 ssl = SSL_new(ssl_ctx); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
320 if (ssl == NULL) { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
321 i_error("SSL_new() failed: %s", ssl_last_error()); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
322 return -1; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
323 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
324 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
325 if (SSL_set_fd(ssl, fd) != 1) { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
326 i_error("SSL_set_fd() failed: %s", ssl_last_error()); |
1457 | 327 SSL_free(ssl); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
328 return -1; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
329 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
330 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
331 if (socketpair(AF_UNIX, SOCK_STREAM, 0, sfd) == -1) { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
332 i_error("socketpair() failed: %m"); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
333 SSL_free(ssl); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
334 return -1; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
335 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
336 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
337 net_set_nonblock(sfd[0], TRUE); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
338 net_set_nonblock(sfd[1], TRUE); |
1268
0d9f0e617a1a
net_* functions don't anymore set sockets to non-blocking by default.
Timo Sirainen <tss@iki.fi>
parents:
1235
diff
changeset
|
339 net_set_nonblock(fd, TRUE); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
340 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
341 proxy = i_new(struct ssl_proxy, 1); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
342 proxy->refcount = 1; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
343 proxy->ssl = ssl; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
344 proxy->fd_ssl = fd; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
345 proxy->fd_plain = sfd[0]; |
1235 | 346 proxy->ip = *ip; |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
347 |
1544
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
348 hash_insert(ssl_proxies, proxy, proxy); |
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
349 |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
350 proxy->refcount++; |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
351 ssl_handshake(proxy); |
1458
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
352 if (!ssl_proxy_unref(proxy)) { |
1117
71c438e6a40f
STARTTLS handshake failure fixes.
Timo Sirainen <tss@iki.fi>
parents:
1049
diff
changeset
|
353 /* handshake failed. return the disconnected socket anyway |
71c438e6a40f
STARTTLS handshake failure fixes.
Timo Sirainen <tss@iki.fi>
parents:
1049
diff
changeset
|
354 so the caller doesn't try to use the old closed fd */ |
71c438e6a40f
STARTTLS handshake failure fixes.
Timo Sirainen <tss@iki.fi>
parents:
1049
diff
changeset
|
355 return sfd[1]; |
71c438e6a40f
STARTTLS handshake failure fixes.
Timo Sirainen <tss@iki.fi>
parents:
1049
diff
changeset
|
356 } |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
357 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
358 main_ref(); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
359 return sfd[1]; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
360 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
361 |
1458
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
362 static int ssl_proxy_unref(struct ssl_proxy *proxy) |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
363 { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
364 if (--proxy->refcount > 0) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
365 return TRUE; |
1490 | 366 i_assert(proxy->refcount == 0); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
367 |
1230
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
368 hash_remove(ssl_proxies, proxy); |
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
369 |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
370 (void)net_disconnect(proxy->fd_ssl); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
371 (void)net_disconnect(proxy->fd_plain); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
372 |
1324
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
373 if (proxy->io_ssl_read != NULL) |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
374 io_remove(proxy->io_ssl_read); |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
375 if (proxy->io_ssl_write != NULL) |
13d8f69d4f1a
rewrite, maybe it works properly now.
Timo Sirainen <tss@iki.fi>
parents:
1268
diff
changeset
|
376 io_remove(proxy->io_ssl_write); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
377 if (proxy->io_plain_read != NULL) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
378 io_remove(proxy->io_plain_read); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
379 if (proxy->io_plain_write != NULL) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
380 io_remove(proxy->io_plain_write); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
381 |
1457 | 382 SSL_free(proxy->ssl); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
383 i_free(proxy); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
384 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
385 main_unref(); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
386 return FALSE; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
387 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
388 |
1458
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
389 static void ssl_proxy_destroy(struct ssl_proxy *proxy) |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
390 { |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
391 if (!proxy->destroyed) { |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
392 proxy->destroyed = TRUE; |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
393 ssl_proxy_unref(proxy); |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
394 } |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
395 } |
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
396 |
1492
383d87166963
Generate temporary RSA key when requested. Could be slow, should do some
Timo Sirainen <tss@iki.fi>
parents:
1490
diff
changeset
|
397 static RSA *ssl_gen_rsa_key(SSL *ssl __attr_unused__, |
383d87166963
Generate temporary RSA key when requested. Could be slow, should do some
Timo Sirainen <tss@iki.fi>
parents:
1490
diff
changeset
|
398 int is_export __attr_unused__, int keylength) |
383d87166963
Generate temporary RSA key when requested. Could be slow, should do some
Timo Sirainen <tss@iki.fi>
parents:
1490
diff
changeset
|
399 { |
383d87166963
Generate temporary RSA key when requested. Could be slow, should do some
Timo Sirainen <tss@iki.fi>
parents:
1490
diff
changeset
|
400 return RSA_generate_key(keylength, RSA_F4, NULL, NULL); |
383d87166963
Generate temporary RSA key when requested. Could be slow, should do some
Timo Sirainen <tss@iki.fi>
parents:
1490
diff
changeset
|
401 } |
383d87166963
Generate temporary RSA key when requested. Could be slow, should do some
Timo Sirainen <tss@iki.fi>
parents:
1490
diff
changeset
|
402 |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
403 void ssl_proxy_init(void) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
404 { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
405 const char *certfile, *keyfile, *paramfile; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
406 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
407 certfile = getenv("SSL_CERT_FILE"); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
408 keyfile = getenv("SSL_KEY_FILE"); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
409 paramfile = getenv("SSL_PARAM_FILE"); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
410 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
411 if (certfile == NULL || keyfile == NULL || paramfile == NULL) { |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
412 /* SSL support is disabled */ |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
413 return; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
414 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
415 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
416 SSL_library_init(); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
417 SSL_load_error_strings(); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
418 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
419 if ((ssl_ctx = SSL_CTX_new(SSLv23_server_method())) == NULL) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
420 i_fatal("SSL_CTX_new() failed"); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
421 |
1544
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
422 SSL_CTX_set_options(ssl_ctx, SSL_OP_ALL); |
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
423 |
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
424 if (SSL_CTX_set_cipher_list(ssl_ctx, SSL_CIPHER_LIST) != 1) { |
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
425 i_fatal("Can't set cipher list to '%s': %s", |
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
426 SSL_CIPHER_LIST, ssl_last_error()); |
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
427 } |
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
428 |
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
429 if (SSL_CTX_use_certificate_chain_file(ssl_ctx, certfile) != 1) { |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
430 i_fatal("Can't load certificate file %s: %s", |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
431 certfile, ssl_last_error()); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
432 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
433 |
1544
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
434 if (SSL_CTX_use_RSAPrivateKey_file(ssl_ctx, keyfile, |
ac6ee442376d
OpenSSL proxy changes - hopefully fixes something. Also don't crash with
Timo Sirainen <tss@iki.fi>
parents:
1492
diff
changeset
|
435 SSL_FILETYPE_PEM) != 1) { |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
436 i_fatal("Can't load private key file %s: %s", |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
437 keyfile, ssl_last_error()); |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
438 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
439 |
1492
383d87166963
Generate temporary RSA key when requested. Could be slow, should do some
Timo Sirainen <tss@iki.fi>
parents:
1490
diff
changeset
|
440 if (SSL_CTX_need_tmp_RSA(ssl_ctx)) |
383d87166963
Generate temporary RSA key when requested. Could be slow, should do some
Timo Sirainen <tss@iki.fi>
parents:
1490
diff
changeset
|
441 SSL_CTX_set_tmp_rsa_callback(ssl_ctx, ssl_gen_rsa_key); |
383d87166963
Generate temporary RSA key when requested. Could be slow, should do some
Timo Sirainen <tss@iki.fi>
parents:
1490
diff
changeset
|
442 |
1230
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
443 ssl_proxies = hash_create(default_pool, default_pool, 0, NULL, NULL); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
444 ssl_initialized = TRUE; |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
445 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
446 |
1230
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
447 static void ssl_proxy_destroy_hash(void *key __attr_unused__, void *value, |
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
448 void *context __attr_unused__) |
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
449 { |
1458
98362534b2c7
Unexpected SSL connection errors sometimes crashed
Timo Sirainen <tss@iki.fi>
parents:
1457
diff
changeset
|
450 ssl_proxy_unref(value); |
1230
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
451 } |
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
452 |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
453 void ssl_proxy_deinit(void) |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
454 { |
1230
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
455 if (!ssl_initialized) |
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
456 return; |
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
457 |
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
458 hash_foreach(ssl_proxies, ssl_proxy_destroy_hash, NULL); |
e6d2b8c78519
Keep list of the SSL proxies, so they're deinitialized properly if we have
Timo Sirainen <tss@iki.fi>
parents:
1215
diff
changeset
|
459 hash_destroy(ssl_proxies); |
1232
f7da7d46e3f2
destroy proxies before destroying ssl context
Timo Sirainen <tss@iki.fi>
parents:
1231
diff
changeset
|
460 |
f7da7d46e3f2
destroy proxies before destroying ssl context
Timo Sirainen <tss@iki.fi>
parents:
1231
diff
changeset
|
461 SSL_CTX_free(ssl_ctx); |
1049
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
462 } |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
463 |
c41787e8c3f4
Moved common login process code to login-common, created pop3-login.
Timo Sirainen <tss@iki.fi>
parents:
diff
changeset
|
464 #endif |